CVE-2025-51567
critical · 9.1A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.
9.1
CVSS
0.4%
EPSS (exploit prob.)
34th
EPSS percentile
2026-01-12
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jayesh | online_exam_system | 1.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-51567